Architecture and Data Model Review
Deep critical review of SecurityV0 architecture and data model with evidence-grade gaps, risk analysis, and prioritized improvements
Deep critical review of SecurityV0 architecture and data model with evidence-grade gaps, risk analysis, and prioritized improvements
Architecture of the rule-based drift detection system — how scope, ownership, and reachability drift evaluators work, how findings are produced, and how the remediation service maps findings to pri...
Sprint priority #2 plan: surface drift signals in a governance-conditions card (Status / Condition / Evidence) at both authority-path and cluster levels, extending the G3 backend with the Notion-spec card format.
Consolidated implementation plan for Exposure Aggregation APIs (G1), Remediation Content Generation (G2), and Scope Drift UX (G3)
Canonical definitions for SecurityV0 domain terminology — NHI, execution chains, entity types (identity, workload, connection, credential, owner), relationship types (RUNS_AS, CALLS, INVOKES, USES,...
W1 Gap 3 plan: enrich the scope-drift Finding Detail page so it tells the 'so what' story (which roles were added, what they grant, what changed) rather than only stating drift occurred.
Founder feedback on the March 29 Wiz UX pattern analysis, with explicit direction on remediation aggregation, finding-detail structure, and scope-drift presentation.
Product requirements for GitHub Zombie & Scope Evidence Engine (v0)